Feb 28, 2025 · 15m · a16z

How to use DeepSeek safely

AI Security Researcher · 10m spoken Joel de la Garza · 3m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this episode of the a16z podcast, host Joel de la Garza and Promptfoo CEO Ian Webster analyze the security, censorship, and enterprise risks associated with China's open-source DeepSeek AI model. They outline key vulnerabilities, contrast its hardcoded political guardrails against Western alternatives, and provide actionable deployment guidance for enterprise security leaders.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The host as informed peer 4.2 Guest teaching 4.6 Guest disagreement 1.4 The host pushing back 2.0
05100:0010:000:34–2:59 · The host as informed peer 3/10 a16z Podcast Title Sequence Joel introduces the guest's blog post and sets up the framing around DeepSeek's open source release and China origins. The guest collaboratively explains red teaming research and prompt injection vulnerabilities without any conflict.2:59–5:56 · The host as informed peer 4/10 Analyzing DeepSeek's Political Censorship and Guardrails Joel offers domain context by bringing up Wiz research on DeepSeek infrastructure and OpenAI learning curves. The guest educates the host with benchmark data showing DeepSeek performs 20% worse than GPT on jailbreak resilience.5:56–8:55 · The host as informed peer 3/10 Self-Hosting vs Cloud Hosting and Hidden Security Risks The guest corrects a widespread internet misconception that self-hosting DeepSeek removes political censorship, clarifying that hard guardrails remain active regardless. Joel listens and acknowledges the security implications.8:55–13:06 · The host as informed peer 6/10 Comparing Speech Restrictions: US Flagship Models vs DeepSeek The guest reveals surprising data showing US models like Anthropic Claude censor Chinese political topics at rates equal to DeepSeek. When the guest hesitates on terminology, Joel firmly interjects to define the behavior as censorship and draws insightful conclusions on Western commentator hypocrisy.13:06–15:14 · The host as informed peer 5/10 Enterprise Safety Recommendations and Deployment Strategy Joel synthesizes the guest's technical warnings into a clean enterprise strategy recommendation to wait for alternative open source implementations. The guest agrees and elaborates on DeepSeek's usability flaws.0:34–2:59 · Guest teaching 3/10 a16z Podcast Title Sequence Joel introduces the guest's blog post and sets up the framing around DeepSeek's open source release and China origins. The guest collaboratively explains red teaming research and prompt injection vulnerabilities without any conflict.2:59–5:56 · Guest teaching 5/10 Analyzing DeepSeek's Political Censorship and Guardrails Joel offers domain context by bringing up Wiz research on DeepSeek infrastructure and OpenAI learning curves. The guest educates the host with benchmark data showing DeepSeek performs 20% worse than GPT on jailbreak resilience.5:56–8:55 · Guest teaching 6/10 Self-Hosting vs Cloud Hosting and Hidden Security Risks The guest corrects a widespread internet misconception that self-hosting DeepSeek removes political censorship, clarifying that hard guardrails remain active regardless. Joel listens and acknowledges the security implications.8:55–13:06 · Guest teaching 5/10 Comparing Speech Restrictions: US Flagship Models vs DeepSeek The guest reveals surprising data showing US models like Anthropic Claude censor Chinese political topics at rates equal to DeepSeek. When the guest hesitates on terminology, Joel firmly interjects to define the behavior as censorship and draws insightful conclusions on Western commentator hypocrisy.13:06–15:14 · Guest teaching 4/10 Enterprise Safety Recommendations and Deployment Strategy Joel synthesizes the guest's technical warnings into a clean enterprise strategy recommendation to wait for alternative open source implementations. The guest agrees and elaborates on DeepSeek's usability flaws.0:34–2:59 · Guest disagreement 1/10 a16z Podcast Title Sequence Joel introduces the guest's blog post and sets up the framing around DeepSeek's open source release and China origins. The guest collaboratively explains red teaming research and prompt injection vulnerabilities without any conflict.2:59–5:56 · Guest disagreement 2/10 Analyzing DeepSeek's Political Censorship and Guardrails Joel offers domain context by bringing up Wiz research on DeepSeek infrastructure and OpenAI learning curves. The guest educates the host with benchmark data showing DeepSeek performs 20% worse than GPT on jailbreak resilience.5:56–8:55 · Guest disagreement 2/10 Self-Hosting vs Cloud Hosting and Hidden Security Risks The guest corrects a widespread internet misconception that self-hosting DeepSeek removes political censorship, clarifying that hard guardrails remain active regardless. Joel listens and acknowledges the security implications.8:55–13:06 · Guest disagreement 1/10 Comparing Speech Restrictions: US Flagship Models vs DeepSeek The guest reveals surprising data showing US models like Anthropic Claude censor Chinese political topics at rates equal to DeepSeek. When the guest hesitates on terminology, Joel firmly interjects to define the behavior as censorship and draws insightful conclusions on Western commentator hypocrisy.13:06–15:14 · Guest disagreement 1/10 Enterprise Safety Recommendations and Deployment Strategy Joel synthesizes the guest's technical warnings into a clean enterprise strategy recommendation to wait for alternative open source implementations. The guest agrees and elaborates on DeepSeek's usability flaws.0:34–2:59 · The host pushing back 1/10 a16z Podcast Title Sequence Joel introduces the guest's blog post and sets up the framing around DeepSeek's open source release and China origins. The guest collaboratively explains red teaming research and prompt injection vulnerabilities without any conflict.2:59–5:56 · The host pushing back 2/10 Analyzing DeepSeek's Political Censorship and Guardrails Joel offers domain context by bringing up Wiz research on DeepSeek infrastructure and OpenAI learning curves. The guest educates the host with benchmark data showing DeepSeek performs 20% worse than GPT on jailbreak resilience.5:56–8:55 · The host pushing back 1/10 Self-Hosting vs Cloud Hosting and Hidden Security Risks The guest corrects a widespread internet misconception that self-hosting DeepSeek removes political censorship, clarifying that hard guardrails remain active regardless. Joel listens and acknowledges the security implications.8:55–13:06 · The host pushing back 4/10 Comparing Speech Restrictions: US Flagship Models vs DeepSeek The guest reveals surprising data showing US models like Anthropic Claude censor Chinese political topics at rates equal to DeepSeek. When the guest hesitates on terminology, Joel firmly interjects to define the behavior as censorship and draws insightful conclusions on Western commentator hypocrisy.13:06–15:14 · The host pushing back 2/10 Enterprise Safety Recommendations and Deployment Strategy Joel synthesizes the guest's technical warnings into a clean enterprise strategy recommendation to wait for alternative open source implementations. The guest agrees and elaborates on DeepSeek's usability flaws.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 0% · guest 100%0:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 6:35 Refuting local deployment myth

The guest forcefully rejects widespread online chatter and host assumptions that locally running DeepSeek avoids political guardrails.

Hardest push from the host ▶ 11:05 Host asserts definition of censorship

When the guest equivocates on whether Western model refusals count as censorship, Joel firmly interrupts to insist that it is censorship.

Biggest teaching moment ▶ 11:10 Claude censorship parity revelation

The guest educates the host with benchmark data revealing Anthropic Claude censors sensitive Chinese political topics at the exact same 85% rate as DeepSeek.

The host holds their own ▶ 12:09 Critique of Western commentary hypocrisy

Joel demonstrates strong analytical domain expertise by synthesizing the benchmark data to call out the hypocrisy of American commentators criticizing Chinese models while Western models do the same.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
a16z Podcast Title Sequence 3311 Joel introduces the guest's blog post and sets up the framing around DeepSeek's open source release and China origins. The guest collaboratively explains red teaming research and prompt injection vulnerabilities without any conflict.
Analyzing DeepSeek's Political Censorship and Guardrails 4522 Joel offers domain context by bringing up Wiz research on DeepSeek infrastructure and OpenAI learning curves. The guest educates the host with benchmark data showing DeepSeek performs 20% worse than GPT on jailbreak resilience.
Self-Hosting vs Cloud Hosting and Hidden Security Risks 3621 The guest corrects a widespread internet misconception that self-hosting DeepSeek removes political censorship, clarifying that hard guardrails remain active regardless. Joel listens and acknowledges the security implications.
Comparing Speech Restrictions: US Flagship Models vs DeepSeek 6514 The guest reveals surprising data showing US models like Anthropic Claude censor Chinese political topics at rates equal to DeepSeek. When the guest hesitates on terminology, Joel firmly interjects to define the behavior as censorship and draws insightful conclusions on Western commentator hypocrisy.
Enterprise Safety Recommendations and Deployment Strategy 5412 Joel synthesizes the guest's technical warnings into a clean enterprise strategy recommendation to wait for alternative open source implementations. The guest agrees and elaborates on DeepSeek's usability flaws.

Statements from this episode (14)

Assertion Supported
Webster: DeepSeek is especially vulnerable to basic prompt jailbreaks
“If I had to deploy DeepSeq, I would probably focus on use cases that were not end user facing because DeepSeq is like, especially susceptible to basic jailbreaks.”
Ian Webster Feb 28, 2025 ▶ 0:17
Insight
Ian Webster: AI jailbreaks let attackers pivot within RAG architectures
“Those are often the gateway to messing around with other stuff, right? Like once, once you punch a hole in the defenses with something like a jailbreak, if it's part of a larger system or architecture, like a rag or agent that would give an attacker a lot of r…”
Ian Webster Feb 28, 2025 ▶ 2:28
Assertion Supported
Ian Webster: DeepSeek uses a separate system for political censorship
“For Deep Seek specifically, there was the part that limited speech about politically sensitive topics in China. So this is stuff like, you know, Taiwan or Tiananmen Square, that kind of thing. And it's pretty clear that that was Basically a separate system fro…”
AI Security Researcher Feb 28, 2025 ▶ 3:02
Assertion Supported
Webster: DeepSeek returns CCP propaganda or refusals on Tiananmen Square
“If you ask it about Tiananmen Square or whatever, it will either give you a refusal or it will give you like this long diatribe of The CCP party line, like, you know, nothing happened. We believe in harmony in China and blah, blah, blah.”
AI Security Researcher Feb 28, 2025 ▶ 3:37
Assertion Not checkable as stated
Webster: DeepSeek performs 20% worse than GPT on jailbreak benchmarks
“On our benchmarks, it performs about 20% worse.”
AI Security Researcher Feb 28, 2025 ▶ 4:43
Assertion Not checkable as stated
Webster: DeepSeek's safety is on par with early GPT-3.5 from 2023
“Qualitatively, what we see is performance on par with GPT 3.5, which is to say, you know, in 2023, when open AI launched GPT, there were there were a bunch of like zero day, really simple jailbreaks and deep seek is essentially susceptible to all of those.”
AI Security Researcher Feb 28, 2025 ▶ 4:56
Assertion Supported
Webster: Self-hosting DeepSeek does not remove built-in political censorship
“If you run it locally or if you use any of these US providers, which have, you know, spun it up and are serving it you get the same level of censorship. The only difference there is that the China hosted version has an additional guardrail that looks at output…”
Ian Webster Feb 28, 2025 ▶ 6:50
Assertion Supported
Webster: DeepSeek hard-censors 85% of politically sensitive topics in Promptfoo benchmark
“We did a benchmark on Chinese politically sensitive topics that, that found that about 85% of those topics in our test set were hard censored.”
Ian Webster Feb 28, 2025 ▶ 7:47
Assertion Contradicted
Ian Webster: Anthropic Claude censorship matches DeepSeek on Chinese political topics
“Sure. Yeah. So, I mean, the level of censorship here is like Anthropic Claude is actually on par with DeepSeq.”
Ian Webster Feb 28, 2025 ▶ 11:10
Assertion Supported
Ian Webster: OpenAI's GPT refuses ~40% of sensitive Chinese political prompts
“Yeah, but still around 40% as opposed to 85% on this particular test set.”
Ian Webster Feb 28, 2025 ▶ 11:34
Assertion Open · timeframe Feb 2028
Ian Webster: xAI's Grok shows lowest censorship on Chinese political topics
“And then this is probably not surprising, but there's, there is one large foundation model that does especially well on the censorship benchmark, which is Grok from XAI is, is like a relatively free model. When it comes to the sensitive Chinese political topic…”
Ian Webster Feb 28, 2025 ▶ 11:46
Prediction Held up
Webster: Equivalent open-source reasoning models will arrive within weeks
“What I've been telling most people who ask is like, let's just wait a few weeks and there will be an open source model that, that implements this reinforcement learning technique and you, you'll, you'll get great reasoning on par with what we see from deep see…”
Ian Webster Feb 28, 2025 ▶ 13:42
Assertion Not checkable as stated
Webster: DeepSeek is slow, verbose, and outputs random Chinese characters
“Deep, deep seek isn't really a great daily driver. It's very slow. It's verbose and you know, it like throws random Chinese characters in, in its answers and stuff, stuff like that.”
Ian Webster Feb 28, 2025 ▶ 14:19
Opinion
Webster: Enterprises should delay deploying DeepSeek until stable alternatives emerge
“The excitement around it is well warranted, but I think in an enterprise or infrastructure context, I would probably wait for something that is more stable and then doesn't have these questions hanging over it.”
Ian Webster Feb 28, 2025 ▶ 14:42
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.